Security Basics mailing list archives

Re: Enterprise Log Management Systems


From: Tremaine Lea <security-basics () ddiction com>
Date: Wed, 25 Apr 2007 21:57:17 -0600


We use Arcsight in our environment, and it works very well. It handles logging from a wide variety of devices and OS's such as Cisco, Tipping Point IPS, Nokia, Checkpoint as well as standard syslog events and AD events. They've got pretty strong support as well.

There's a great deal of built in reporting and rules set up by default, as well as compliance reports/rules etc for about 8 different compliance sets such as SOX.

Alerting is also pretty solid.

About the only solution I've seen recently that performs in the same area as strongly is the solution from RSA, but I haven't used theirs.

---

Tremaine Lea
Network Security Consultant

Be in pursuit of equality, but not at the expense of excellence.


On 25-Apr-07, at 7:56 AM, Tornado wrote:

Hi All,

I would like to know which are the best Enterprise log management systems out there in the market. Both commercial and Open source are fine.
Here are the requirements:

1. Log collection from variety of systems like Windows, Linux, Routers and firewalls.

2. Analysis of collected logs and co-relation.

3. Report generation for the activities for starndards like ISO 270001

4. Email/SMS alerts.

Thanks in advance.

----------------------------------------------------------------------
Get a free email address with REAL anti-spam protection.
http://www.bluebottle.com





Current thread: